Showing posts with label Quarkslab. Show all posts
Showing posts with label Quarkslab. Show all posts

Tuesday, July 25, 2017

ICS-CERT Published an Alert, an Advisory and 4 Updates

Today the DHS ICS-CERT published a control system security alert for the CRASHOVERRIDE malware and a control system security advisory for products from NXP. The NXP advisory was previously published on the NCCIC Portal on June 1st, 2017. ICS-CERT also updated four previously issued control system advisories for products from Siemens (3) and GE.

CRASHOVERRIDE Alert


This alert briefly describes the CRASHOVERRIDE malware. This malware was previously identified by ESET (on June 12th), Dragos (on June 12th) and US CERT (on June 12th) which ICS-CERT fully credits. All three reports provide much more information than does the ICS-CERT Alert. ICS-CERT has provided a different set of YARA rules for the detection of the malware than those previously published by Dragos. The ICS-CERT rules appear to target different portions of the malware.

NXP Advisory


This advisory describes two vulnerabilities in the NXP i.MX Devices, used on logic boards. The vulnerabilities were reported by Quarkslab. These are hardware vulnerabilities that generally cannot be corrected by a software fix. ICS-CERT notes that the vulnerabilities “are only exploitable when the device is placed in security enabled mode”.

The two reported vulnerabilities are:

• Stack-based buffer overflow - CVE-2017-7936; and
• Improper certificate validation - CVE-2017-7932

ICS-CERT reports that a successful attack (by an uncharacterized attacker with uncharacterized access) could exploit the vulnerability to create a denial of service attack or to load an unauthorized image on the device affecting secure boot.

NOTE: These are not stand-alone devices, they are chip sets found on circuit boards on unnamed devices from unnamed supplier. Hopefully one (or more) of those downstream suppliers will develop a successful mitigation for this problem on their devices. But, it has been almost two months since notification was made to those vendors….

S7-300 Update


This update provides new information on an advisory that was originally published on December 13th, 2016 and then updated on May 9th, 2017. The update provides a link to a firmware update for the  S7-CPU 410 CPUs.

GE Update


This update provides new information on an advisory that was originally published on April 27th, 2017, and updated on May 18th, 2017. The new update identifies 8 legacy products that are affected by the vulnerability. It also provides links to previously identified firmware versions and newly mitigated products, including the newly identified legacy products. The firmware update for the URplus platform is still expected to be released this month.

PROFINET 1 update


This update provides new information on an advisory that was originally published on May 9th, 2017 and updated on June 15th, 2017, on June 20th, 2017, and again on July 6th, 2017. The update provides updated version information and mitigation information for the SINEMA Server: All versions < V14.


PROFINET 2 update


This update provides new information on an advisory that was originally published on May 9th, 2017 and updated on June 15, 2017. The update provides new affected version information and mitigation links for:

• SCALANCE XM400, XR500: All versions prior to V6.1;
• S7-400 PN/DP V6 Incl. F: All versions;
• S7-400-H V6: All versions prior to V6.0.7;
• S7-400 PN/DP V7 Incl. F: All versions;
• S7-410: All versions prior to V8.2;
• SINAMICS S110 w. PN: All versions prior to V4.4 SP3 HF5;
• SINAMICS S120 V4.7: All versions prior to V4.7 H27; and

• SINAMICS V90 w. PN: All versions prior to V1.1

Thursday, April 9, 2015

ICS-CERT Publishes Siemens HMI Advisory

This morning the DHS ICS-CERT published an advisory for multiple vulnerabilities in a variety of Siemens HMI devices. The vulnerabilities were reported by the Quarkslab team and Ilya Karpov from Positive Technologies. Siemens has produced updates for most affected products (others are still in the works) but there is no indication that the researchers have been provided an opportunity to verify the efficacy of the fixes.

The vulnerabilities are:

∙ Man-in-the-Middle - CVE-2015-1601;
∙ Resource exhaustion - CVE-2015-2822; and
∙ Use of password hash instead of password for authentication - CVE-2015-2823

ICS-CERT reports that a moderately skilled attacker could remotely exploit these vulnerabilities to conduct man-in-the-middle attacks, denial‑of‑ service attacks, and possibly authenticate themselves as valid users depending on the vulnerability exploited.

With the large number of systems susceptible to these vulnerabilities I would suspect that they were only reported in one or two systems by the researchers. This would fit with the recent Siemens history of self-identifying vulnerabilities. If true Siemens is to be congratulated on their commitment improving the security of their systems. Some vendors recently identified with vulnerabilities in a portion of their product line would do well to emulate the Siemens model and proactively determine if the same vulnerability affects similar devices.

NOTE 1: It only took ICS-CERT a day to publish this advisory, they are getting better. My TWITTER followers will remember that this was announced yesterday morning my Siemens.


NOTE 2: Siemens appears to have developed a complicated internal method of determining when ‘enough’ systems have protections available to make it worthwhile to publish their advisories. We have seen this in a number of instances lately where ‘most’ of the affected systems have fixes in place and the other fixes come out over subsequent weeks and months. I hope that the researchers involved are aware of the risks that Siemens is taking with their more timely publication of vulnerabilities.

Thursday, February 19, 2015

ICS-CERT Publishes Another Siemens Advisory

This morning the DHS ICS-CERT published another advisory for twin vulnerabilities in the Siemens SIMATIC STEP 7 TIA Portal. Each advisory was separately discovered by Quarkslab team and Dmitry Sklyarov with PT-Security. Siemens has produced a patch to mitigate the vulnerabilities, but there is no indication that either research team has been given the opportunity to verify the efficacy of the patch.


The two vulnerabilities are:

● Man-in-the Middle vulnerability - CVE-2015-1601; and
● Use of password with insufficient computational effort - CVE-2015-1602

ICS-CERT reports that it would be moderately difficult to construct a workable exploit for these two vulnerabilities. Siemens reports that access to the network path between client and server would be required for the first vulnerability and access to TIA project files would be required for the second.

Why Siemens

At some point we have to wonder why we are seeing so many Siemens advisories. In many cases (but certainly not even most) the answer is self-reporting and that is a mark of a current commitment to security. But sooooo many vulnerabilities, surely that is the sign of a basic problem?

Yes, there were certainly problems with the way that most of these programs were originally written. The mistakes we are seeing seem so basic now, but that is because we have been seeing them throughout the industry for the last few years. Siemens is not paying for the mistakes that they and most of the rest of the industry made back when security was a ‘non-issue’ because control systems were air gapped and so hard to understand.

Siemens is now facing much the same problem that Micrsoft faced twenty years ago. Because of their size, familiarity and availability, researchers around the world are taking a hard look at Siemens products, knowing that they are going to find vulnerabilities. It many not be quite shooting fish in a barrel, but it is certainly fishing in a freshly stocked pond.

Many of these researchers are going to start to move on to the other suppliers in the field using the skills they honed on working on Siemens gear. There will be more advisories for other vendors and people will laugh at how easy they were to find; unless the other vendors internalize the searches and fix them before the researchers find them.


And the Siemens advisories will continue. Siemens makes ever more complex products; with more and more capabilities. Mistakes will be made. More importantly researchers (of whatever hat color) are also getting more and more sophisticated. They will find new types of vulnerabilities that we have not even thought about yet. Security designers and researchers will continue to be locked in a war of improving capabilities. And we users; we will be better for it.
 
/* Use this with templates/template-twocol.html */